HIGH-LEVEL CROSSWALK
The IT Top 10, mapped to NIST 800-171 & CMMC
A high-level view of how each Brilliant at the Basics IT practice lines up with the NIST SP 800-171 control families and CMMC domains. Use it to orient — then open each practice guide for the specifics.
Orientation, not a control-level mapping
This shows the primary family each practice supports. Real 800-171 / CMMC compliance touches many controls per practice and depends on your environment. Independent mappings are aids, not authoritative equivalence or compliance determinations.
| Practice | Primary NIST SP 800-171 family | CMMC domain | Also supports | |
|---|---|---|---|---|
| IT-01 Phishing-Resistant MFA | Identification & Authentication (3.5) | IA | Access Control | Guide → |
| IT-02 Asset Inventory | Configuration Management (3.4) | CM | Risk Assessment | Guide → |
| IT-03 Technical Debt Reduction | System & Information Integrity (3.14) | SI, CM | Risk Assessment | Guide → |
| IT-04 Flexible Technology Stack | Configuration Management (3.4) | CM | System & Comms Protection | Guide → |
| IT-05 Logical Segmentation | System & Communications Protection (3.13) | SC | Access Control | Guide → |
| IT-06 Vulnerability Management | Risk Assessment (3.11) | RA, SI | System & Info Integrity | Guide → |
| IT-07 Security in the SDLC | System & Information Integrity (3.14) | SI, CM | Security Assessment | Guide → |
| IT-08 Secure AI & Data Protection | Access Control (3.1) · SC Protection (3.13) | AC, SC | Media Protection | Guide → |
| IT-09 Backup & Disaster Recovery | Media Protection (3.8) | MP | Recovery | Guide → |
| IT-10 Workforce Readiness | Awareness & Training (3.2) | AT | — | Guide → |
Working the OT side too?
The OT Top 10 maps against NIST SP 800-82 and the CSF. See the OT Top 10 and the full framework mappings on each practice guide.